MyBulletinBoard vulnerabilities and new updates

By N-Stalker Team on January 8, 2007

N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.

You will be able to download it automatically in the following versions:

  • N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
    • WSI Update (N-Stalker Update Manager)
  • N-Stealth HTTP Security Scanner (database update 188)
    • Automatic DB Update

You should be able to receive it automatically next time you execute the scanner.

If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.

If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)

This release has included the following vulnerabilities:

  • VUBB 0.2.1 Email Parameter SQL Injection Vulnerability
  • WeBBoA 1.1 ID Parameter SQL Injection Vulnerability
  • Maximus SchoolMAX 4.0.1 Error_msg Parameter Cross-Site Scripting Vulnerability
  • thinkWMS 1.0 Multiple SQL Injection Vulnerabilities
  • IMGallery 2.4 Galeria.PHP Multiple SQL Injection Vulnerabiliies
  • Ad Manager Pro 2.6 IPath Multiple Remote File Include Vulnerabilities
  • Thinkfactory UltimateGoogle 1.00 Index.PHP Cross-Site Scripting Vulnerability
  • Bluehouse Project PHPTrader 4.9 Multiple SQL Injection Vulnerabilities
  • Ultimate Estate 1.0 Multiple Input Validation Vulnerabilities
  • AEwebworks aeDating 4.1 Software Multiple Cross-Site Scripting Vulnerabilities
  • Lighthouse Development Squirrelcart 2.2 Cart_Content.PHP Remote File Include Vulnerability
  • Ultimate eShop 1.0 Index.CGI Cross-Site Scripting Vulnerability
  • MyPHP Guestbook 2.0.1 Multiple Cross Site Scripting Vulnerabilities
  • Enterprise Groupware System 1.2.4 Index.PHP Cross-Site Scripting Vulnerability
  • DataLife Engine 4.1 Subaction SQL Injection Vulnerability
  • Azureus 2.4.2 Index.TMPL Cross-Site Scripting Vulnerability
  • Namo DeepSearch 4.5 Mclient.CGI Cross-Site Scripting Vulnerability
  • V3 Chat Instant Messenger Multiple Input Validation Vulnerabilities
  • PHP Event Calendar 4.2 SQL Injection Vulnerability
  • WoltLab Burning Board 2.3.1 Multiple SQL Injection Vulnerabilities
  • MyBulletinBoard 1.1.3 Usercp.PHP SQL Injection Vulnerability
  • NetSoft SmartNet Search.ASP Cross-Site Scripting Vulnerabilities
  • Softbiz Dating Script 1.0 Multiple SQL Injection Vulnerabilities
  • Dating Agent 4.7.1 Multiple Input Validation Vulnerabilities
  • W-Agora 4.2 Inc_Dir Multiple Remote File Include Vulnerabilities

This entry was posted in N-Stalker Latest Updates. Bookmark the permalink.